Skip to main content
EPSS 0.2%top 89%

Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview

0
High
Published: 06/23/2026 (06/23/2026, 17:23:42 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Satellite provides a container image that you can use to run an MCP server locally. The MCP server for Satellite is designed for advanced reporting and data analysis that leverages AI capabilities. You can use it to generate dynamic and comprehensive reports from your Satellite inventory.

Affected software

Affected versions
>=6.19Red HatRed Hat SatelliteRed Hat Satellite 6.19amd64registry.redhat.io/satellite/foreman-mcp-server-rhel9@sha256:0130440128fabdff55b67256d444d2edca40912b65e65b8569964738f85d3069_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:39:24 UTC

Technical Analysis

CVE-2026-12112 is a session management vulnerability in the foreman-mcp-server used by Red Hat Satellite. The MCP server improperly caches authenticated client connections and trusts non-secret session IDs without revalidating authentication tokens. Additionally, newly created session IDs are logged to standard logs, increasing exposure risk. This flaw allows unauthenticated attackers to hijack active administrative sessions, resulting in privilege escalation and the ability to execute code across the infrastructure. The vulnerability is associated with CWE-287 (Improper Authentication) and CWE-532 (Information Exposure Through Log Files). Red Hat has not yet provided a patch or practical mitigation for this issue. The advisory references Red Hat Satellite 6.19 and the satellite/foreman-mcp-server-rhel9 container image as affected components.

Potential Impact

Successful exploitation allows an unauthenticated attacker to hijack administrative sessions, escalate privileges, and execute code infrastructure-wide. This can lead to full compromise of the affected Red Hat Satellite environment. The vulnerability impacts confidentiality, integrity, and availability of the system.

Mitigation Recommendations

Red Hat has not identified any practical mitigation for this vulnerability at this time. Users should monitor Red Hat advisories and update the affected packages immediately once a fix becomes available. Until then, no specific workaround or mitigation is provided by Red Hat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:28438
Cve Count
2
Additional Cves
["CVE-2026-12112"]
Cvss Version
3.1

Threat ID: 6a3c0cf2eed863c81e239acc

Added to database: 06/24/2026, 16:59:30 UTC

Last enriched: 08/16/2026, 18:39:24 UTC

Last updated: 09/19/2026, 22:01:38 UTC

Views: 98

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses